Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-40706

Опубликовано: 21 апр. 2026
Источник: debian
EPSS Низкий

Описание

In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered on the READ path (stat, readdir, open) when processing a security descriptor with multiple ACCESS_DENIED ACEs containing WRITE_OWNER from distinct group SIDs.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ntfs-3gfixed1:2026.2.25-1package

Примечания

  • https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-4cwv-5285-63v9

  • Fixed by: https://github.com/tuxera/ntfs-3g/commit/e48e1ef2a1fcff13a590c2224ec21c5bd5d3e92e (2026.2.25)

EPSS

Процентиль: 6%
0.00165
Низкий

Связанные уязвимости

CVSS3: 8.4
ubuntu
4 месяца назад

In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered on the READ path (stat, readdir, open) when processing a security descriptor with multiple ACCESS_DENIED ACEs containing WRITE_OWNER from distinct group SIDs.

CVSS3: 8.4
nvd
4 месяца назад

In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered on the READ path (stat, readdir, open) when processing a security descriptor with multiple ACCESS_DENIED ACEs containing WRITE_OWNER from distinct group SIDs.

CVSS3: 8.4
msrc
4 месяца назад

Описание отсутствует

suse-cvrf
3 месяца назад

Security update for ntfs-3g_ntfsprogs

suse-cvrf
4 месяца назад

Security update for ntfs-3g_ntfsprogs

EPSS

Процентиль: 6%
0.00165
Низкий